Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
80.842 exploits
Exploit-DBVexDay Proof
Pandora FMS 3.1 - Authentication Bypass / Arbitrary File Upload (Metasploit)
CVE-2010-4279remotephp08 ene 2015
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RIESGO
abrir
Exploit-DB
Sefrengo CMS 1.6.0 - SQL Injection
CVE-2015-0919webappsphp07 ene 2015
Multiple SQL injection vulnerabilities in the administrative backend in Sefrengo before 1.6.1 allow remote administrator
23RIESGO
abrir
Exploit-DB
Microweber CMS 0.95 - SQL Injection
CVE-2014-9464webappsphp07 ene 2015
SQL injection vulnerability in Category.php in Microweber CMS 0.95 before 20141209 allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DB
Pirelli ADSL2/2+ Wireless Router P.DGA4001N - Information Disclosure
CVE-2015-0554webappshardware07 ene 2015
The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly rest
50RIESGO
abrir
Exploit-DB
AdaptCMS 3.0.3 - Multiple Vulnerabilities
CVE-2015-1060webappsphp06 ene 2015
Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect
23RIESGO
abrir
Exploit-DB
AdaptCMS 3.0.3 - Multiple Vulnerabilities
CVE-2015-1058webappsphp06 ene 2015
Multiple cross-site scripting (XSS) vulnerabilities in AdaptCMS 3.0.3 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir
Exploit-DB
Nexus 5 Android 5.0 - Local Privilege Escalation
CVE-2014-4322localandroid06 ene 2015
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir
Metasploit300
McAfee ePolicy Orchestrator Authenticated XXE Credentials Exposure
CVE-2015-092206 ene 2015
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers'
23RIESGO
abrir
Metasploit300
McAfee ePolicy Orchestrator Authenticated XXE Credentials Exposure
CVE-2015-092106 ene 2015
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x
23RIESGO
abrir
Exploit-DBVexDay Proof
BulletProof FTP Client - BPS Buffer Overflow (Metasploit)
CVE-2014-2973localwindows06 ene 2015
35RIESGO
abrir
Exploit-DB
AdaptCMS 3.0.3 - Multiple Vulnerabilities
CVE-2015-1059webappsphp06 ene 2015
Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute
23RIESGO
abrir
Exploit-DB
SkinCrafter3 vs2005 3.8.1.0 - Multiple ActiveX Buffer Overflows
CVE-2012-2271remotewindows05 ene 2015
Buffer overflow in the InitLicenKeys function in a certain ActiveX control in SkinCrafter3_vs2005.dll in SkinCrafter 3.0
23RIESGO
abrir
Exploit-DBVexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'welcome' Remote Command Execution (Metasploit)
CVE-2012-0262webappsmultiple05 ene 2015
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers
60RIESGO
abrir
Metasploit600
ASUS infosvr Auth Bypass Command Execution
CVE-2014-958304 ene 2015
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RIESGO
abrir
Exploit-DBVexDay Proof
ASUSWRT 3.0.0.4.376_1071 - LAN Backdoor Command Execution
CVE-2014-9583remotehardware04 ene 2015
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RIESGO
abrir
Exploit-DB
Crea8Social 2.0 - Cross-Site Scripting Change Interface
CVE-2015-1054webappsphp04 ene 2015
Cross-site scripting (XSS) vulnerability in the Games feature in Crea8Social 2.0 allows remote authenticated users to in
23RIESGO
abrir
Exploit-DBVexDay Proof
e107 2 Bootstrap CMS - Cross-Site Scripting
CVE-2015-1057webappsphp03 ene 2015
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary w
23RIESGO
abrir
Exploit-DB
PhotoPost < 4.85 - Multiple Vulnerabilities
CVE-2005-0273webappsphp03 ene 2015
Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arb
23RIESGO
abrir
Exploit-DB
PhotoPost < 4.85 - Multiple Vulnerabilities
CVE-2005-0274webappsphp03 ene 2015
Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers t
23RIESGO
abrir
Exploit-DB
ReviewPost < 2.84 - Multiple Vulnerabilities
CVE-2005-0272webappsphp02 ene 2015
ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review fil
23RIESGO
abrir
Exploit-DB
ReviewPost < 2.84 - Multiple Vulnerabilities
CVE-2005-0270webappsphp02 ene 2015
Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject a
23RIESGO
abrir
Exploit-DB
ReviewPost < 2.84 - Multiple Vulnerabilities
CVE-2005-0271webappsphp02 ene 2015
Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
Exploit-DB
Absolut Engine 1.73 - Multiple Vulnerabilities
CVE-2014-9435webappsphp01 ene 2015
Multiple SQL injection vulnerabilities in Absolut Engine 1.73 allow remote authenticated users to execute arbitrary SQL
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.1 (x86/x64) - 'ahcache.sys' NtApphelpCacheControl Privilege Escalation
CVE-2015-0002localwindows01 ene 2015
The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1,
43RIESGO
abrir
Exploit-DB
Absolut Engine 1.73 - Multiple Vulnerabilities
CVE-2014-9434webappsphp01 ene 2015
Cross-site scripting (XSS) vulnerability in admin/managerrelated.php in the administrative backend in Absolut Engine 1.7
23RIESGO
abrir
Exploit-DBVexDay Proof
ProjectSend - Arbitrary File Upload (Metasploit)
CVE-2014-9567remotephp31 dic 2014
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RIESGO
abrir
Exploit-DBVexDay Proof
Social Microblogging PRO 1.5 - Persistent Cross-Site Scripting
CVE-2014-9516webappsphp31 dic 2014
Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Metasploit300
ManageEngine Desktop Central Administrator Account Creation
CVE-2014-786231 dic 2014
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at
60RIESGO
abrir
Exploit-DB
PHP-Calendar < 0.10.1 - Arbitrary File Inclusion
CVE-2004-1423webappsphp29 dic 2014
Multiple PHP remote file inclusion vulnerabilities in Sean Proctor PHP-Calendar before 0.10.1, as used in Commonwealth o
28RIESGO
abrir
Exploit-DB
WHM.AutoPilot < 2.4.6.5 - Multiple Vulnerabilities
CVE-2004-1422webappsphp27 dic 2014
WHM AutoPilot 2.4.6.5 and earlier allows remote attackers to gain sensitive information via phpinfo, which reveals php s
23RIESGO
abrir
anteriorpágina 1071 / 2695siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.